CVE-2026-16372

9.8

Mozilla · Firefox, Thunderbird

A privilege escalation vulnerability exists in the DOM Content Processes component of Mozilla Firefox and Thunderbird, allowing for potential full system compromise.

Executive summary

A critical privilege escalation vulnerability in the DOM Content Processes component of Mozilla Firefox and Thunderbird exposes users to potential full system compromise.

Vulnerability

The vulnerability is a privilege escalation flaw located within the DOM Content Processes component. It allows an unauthenticated attacker to achieve total impact on the affected system, though it requires user interaction as indicated by the CVSS vector.

Business impact

The potential for privilege escalation represents a severe risk to organizational security, as it could permit an attacker to execute arbitrary code with elevated permissions. Given the CVSS score of 9.8, this vulnerability must be treated as a high priority, as successful exploitation could lead to unauthorized data access, system-wide compromise, and significant operational disruption.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 153 or later immediately.

Proactive Monitoring: Review system and application logs for unusual process execution patterns or unexpected browser behavior that may indicate an exploitation attempt.

Compensating Controls: Ensure that endpoint protection software is active and fully updated to detect and block malicious payloads typically associated with browser-based exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The critical nature of this privilege escalation flaw necessitates an immediate organization-wide update to Mozilla Firefox and Thunderbird version 153. Security teams should prioritize patching cycles for all endpoints running these applications to eliminate the risk of remote compromise.

More Mozilla CVEs

Sources

Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.